IBM
IBM Planning Analytics Local: vulnerabilidades y CVE
IBM Planning Analytics Local tiene 32 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE32
Últimos 12 meses7
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-13365 | Media (6.5) | 0.17% | — | 13 ago 2026 | IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. |
| CVE-2026-10545 | Alta (7.5) | 0.38% | — | 30 jul 2026 | IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this… |
| CVE-2026-1267 | Media (6.5) | 0.33% | — | 17 mar 2026 | IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities due to lack of proper access controls. |
| CVE-2025-14806 | Media (5.7) | 0.29% | — | 17 mar 2026 | IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing and serving sensitive, user-specific responses as publicly cacheable resources. |
| CVE-2025-36437 | Media (4.3) | 0.21% | — | 9 dic 2025 | IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could aid in further attacks against the system. |
| CVE-2025-36357 | Alta (8) | 0.82% | — | 17 nov 2025 | IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing absolute path sequences… |
| CVE-2025-36299 | Media (4.3) | 0.21% | — | 17 nov 2025 | IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further attacks against the system. |
| CVE-2025-36262 | Media (4.9) | 0.30% | — | 30 sept 2025 | IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of… |
| CVE-2025-36132 | Media (5.4) | 0.19% | — | 30 sept 2025 | IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus… |
| CVE-2025-33005 | Alta (8.8) | 0.25% | — | 1 jun 2025 | IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system. |
| CVE-2025-33004 | Media (6.5) | 0.46% | — | 1 jun 2025 | IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction. |
| CVE-2025-2896 | Media (5.4) | 0.20% | — | 1 jun 2025 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality… |
| CVE-2025-25044 | Media (5.4) | 0.20% | — | 1 jun 2025 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality… |
| CVE-2024-35143 | Crítica (9.1) | 0.43% | — | 4 ago 2024 | IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password… |
| CVE-2024-31908 | Media (5.4) | 0.25% | — | 31 may 2024 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality… |
| CVE-2024-31907 | Media (5.4) | 0.25% | — | 31 may 2024 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially… |
| CVE-2024-31889 | Media (5.4) | 0.25% | — | 31 may 2024 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially… |
| CVE-2023-28520 | Media (5.4) | 0.35% | — | 12 may 2023 | IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially… |
| CVE-2021-29739 | Media (4.9) | 1.1% | — | 10 ago 2021 | IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. X-Force ID: 198846. |
| CVE-2020-4670 | Crítica (9.1) | 2.4% | — | 17 may 2021 | IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit… |
| CVE-2020-4669 | Crítica (9.1) | 1.9% | — | 17 may 2021 | IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A… |
| CVE-2020-4985 | Alta (7.5) | 0.98% | — | 14 may 2021 | IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameters in a query. IBM X-Force ID: 192642. |
| CVE-2020-4649 | Media (4.3) | 0.82% | — | 3 nov 2020 | IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by not invalidating TM1Web user sessions. IBM X-Force ID: 186022. |
| CVE-2020-4645 | Media (5.4) | 0.56% | — | 29 jul 2020 | IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality… |
| CVE-2020-4644 | Media (5.4) | 1.2% | — | 29 jul 2020 | IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this… |
| CVE-2020-4503 | Media (6.1) | 0.85% | — | 2 jun 2020 | IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to… |
| CVE-2020-4431 | Media (5.4) | 0.56% | — | 2 jun 2020 | IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to… |
| CVE-2020-4367 | Alta (7.5) | 0.79% | — | 2 jun 2020 | IBM Planning Analytics Local 2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 179001. |
| CVE-2020-4366 | Media (6.1) | 0.73% | — | 2 jun 2020 | IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to… |
| CVE-2020-4360 | Media (5.4) | 0.65% | — | 2 jun 2020 | IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142